Relationships
#2527 @swamp/aws/certificatemanager/certificate: expose ACM's reported attributes (NotAfter, Type, RenewalEligibility, InUseBy) on read
Opened by kscarmardo-glu · 9/25/2026
Problem
@swamp/aws/certificatemanager/certificate get returns only:
CertificateArn, DomainName, KeyAlgorithm, SubjectAlternativeNames, _identifierAbsent are every attribute ACM's own DescribeCertificate reports:
NotAfter, NotBefore, Type, Status, RenewalEligibility, InUseBy,
RenewalSummary.
Those are the fields you would read a certificate to find out. Without them the type can enumerate certificates but cannot answer whether any of them is about to break something.
Why this matters more than it looks
The two decisive facts are when it expires and whether it can renew itself, and neither is useful alone.
In one account we measured:
| Domain | Type | Days left | Auto-renews |
|---|---|---|---|
mcp-lab-dev.… |
AMAZON_ISSUED |
56 | yes — unremarkable |
*.example.com |
IMPORTED |
54 | no — an outage with a date on it |
Two days apart, opposite meanings. A consumer with only DomainName cannot
distinguish them, and a consumer with only an expiry date would alarm on both
or neither.
This is not hypothetical: we found an IMPORTED, RenewalEligibility: INELIGIBLE wildcard three days from expiry, live on a production load
balancer, with nothing watching it. The model could not have surfaced that.
Proposal
Include ACM's reported attributes in the read path for
@swamp/aws/certificatemanager/certificate.
More generally, this is the same root cause as swamp-club Lab #2487, seen
from the other side: there the generated read schema marks declare-time
properties as required; here it omits report-time properties. Both
follow from generating the read path from a resource schema describing what can
be declared rather than what the service reports. A fix at the generator would
address both, and likely other @swamp/aws/* types.
Current workaround
A local export const extension adding a check_expiry method that calls
DescribeCertificate directly and records days-remaining plus a computed
autoRenews. It works, and the extension guide's step 5 explicitly says to
file this request when extending an official type — but every consumer wanting
certificate expiry has to write the same thing.
Environment
- swamp
20260923.133857.0-sha.819937e2 @swamp/aws/certificatemanagermodel type version2026.08.29.1
Upstream repository: https://github.com/swamp-club/swamp-extensions
Environment
- Extension:
@swamp/aws/certificatemanager@2026.09.24.1 - swamp:
20260923.133857.0-sha.819937e2 - OS:
darwin(aarch64) - Deno:
2.9.7 - Shell:
/bin/bash
Open
No activity in this phase yet.
system commented 9/25/2026, 12:41:58 PM
Classified automatically when this issue was filed.
- Source: Extensions
If you feel this classification is incorrect, add a ripple to tell us so.
Sign in to post a ripple.